Security researchers at F-Secure Labs this week disclosed the discovery of counterfeit Cisco switches. Two versions of the devices, which were unwittingly purchased and deployed by an unnamed IT company, began failing after a software upgrade in the fall of 2019, according to the security firm.
Cisco has a long history of battling counterfeiting of its hardware and outright theft of its software. The switches deemed to be counterfeit in this case, Cisco’s Catalyst 2960-X series switches, were nearly identical to legitimate hardware and operated as expected prior to the introduction of a software upgrade.
“Counterfeit devices quite often work smoothly for a long time, which makes it hard to detect them,” Dmitry Janushkevich, senior consultant at F-Secure Labs, wrote in a report.
“Ultimately, we concluded, with a reasonable level of confidence, that no backdoors had been introduced. Furthermore, we identified the full exploit chain that allowed one of the forged products to function: a previously undocumented vulnerability in a security component, which allowed the device’s secure boot restrictions to be bypassed,” he explained.
However, he added that while no backdoors were identified, F-Secure’s hardware security team determined that the bypassing of security functions resulted in a weakening of the switches’ security posture. “This could allow attackers who have already gained code execution via a network-based attack, for example, an easier way to gain persistence and therefore impact the security of the whole organization,” Janushkevich wrote.
“Reverting the software version did not fix the problem, likely pointing to evidence of data being overwritten during the update process,” Janushkevich added.
Inoperability following a software upgrade is the “biggest indication” that a 2960-X switch is counterfeit, according to F-Secure Labs. Some hard-to-discern but visible differences on the exterior of the counterfeit devices were also revealed during the investigation.
The more prominent differences included misshaped triangles indicating ports, misaligned text, slightly different button shapes, and lighter color shades. Moreover, F-Secure noted that engineering on one of the counterfeit units suggests that the counterfeits “either invested heavily in replicating Cisco’s original design or had access to proprietary engineering documentation to help them create a convincing copy.”
The integrity and quality of Cisco products and services is a top priority for Cisco, a spokesperson for the company told SDxCentral. “Counterfeit products pose serious risks to network quality, performance, safety, and reliability. We recommend customers purchase Cisco products from Cisco or through an authorized partner to ensure customers get genuine and authorized Cisco products,” the spokesperson said in a statement.
The vendor monitors counterfeit activity globally and has a specialized team dedicated to “detecting, deterring, and dismantling counterfeit activities,” the spokesperson added. “Combatting widespread counterfeiting and protecting intellectual property rights are sizable challenges facing the entire technology industry.”
Comments